Blog
Latest Post - What are the EU Cyber Resilience Act (CRA) reporting obligations — and do they apply to you?
TL;DR: The EU Cyber Resilience Act makes security a legal requirement for connected products, and UK businesses selling into the EU are in scope too.
The CRA requires products with digital elements to be secure by design and supported with updates throughout their life
Reporting duties for actively exploited vulnerabilities and severe incidents began on 11 September 2026
Full technical compliance rules apply from 11 December 2027
UK businesses that manufacture, import, distribute or resell products into the EU, including IT resellers, have obligations under the CRA
View Post


